Skip to content
Aqlemy

Legal

Subprocessors

Who processes personal data on our behalf, for what purpose and where.

Version 2026.4

To deliver the platform we engage the parties below. Each one states the role it holds under the GDPR: a processor acts solely on our instructions and for the stated purpose, while an independent controller decides for itself what it does with the data and its own terms apply. Changes to this list are announced to connected organisations in advance.

OVHcloud

The server the platform and database run on, and the storage holding the encrypted backups.

Role:
Hosting and storage
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
FR / NL
Transfer:
Processing within the EEA
Data:
all platform data

Stripe

Processes membership fees, donations, event tickets and the organisation’s own subscription.

Role:
Payments
GDPR role:
Processor for our instructions, and additionally an independent controller for its own legal purposes
Country:
US / IE
Transfer:
EU-US Data Privacy Framework
Data:
email address, name, payment details

PayPro

Only if the organisation enables this integration

Collects only the subscription fee the organisation pays to Aqlemy, for contracts concluded outside the website. This party does not come into contact with data of members, students, parents or teachers: only the organisation’s own business and contact details are sent. On our side Aqlemy is the controller for that, not the organisation. PayPro then processes those details for its own purposes as a payment institution — including the legally required identity check — and is itself a controller for that; there is no processing agreement, and given those statutory duties there cannot be one.

Role:
Payments
GDPR role:
Independent controller — no data processing agreement, its own terms apply
Country:
NL
Transfer:
Processing within the EEA
Data:
email address, name, phone number, address details

one.com

Sends the platform’s email when the organisation has not configured its own mail server.

Role:
Email delivery
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
DK
Transfer:
Processing within the EEA
Data:
email address, content of sent email

Microsoft (Graph, Entra ID)

Only if the organisation enables this integration

Sends email from the organisation’s own Microsoft address, and provides sign-in via Microsoft.

Role:
Email delivery
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
US / EU
Transfer:
EU-US Data Privacy Framework
Data:
email address, content of sent email

Google (SMTP/OAuth)

Only if the organisation enables this integration

Sends email from the organisation’s own Google address.

Role:
Email delivery
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
US
Transfer:
EU-US Data Privacy Framework
Data:
email address, content of sent email

Google Firebase (Cloud Messaging)

Delivers push notifications to the user’s phone.

Role:
Push notifications
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
US
Transfer:
EU-US Data Privacy Framework
Data:
device token for notifications, notification text (may contain names)

Laposta

Only if the organisation enables this integration

Newsletters, only for people who signed up. The organisation connects its own account.

Role:
Email marketing
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
NL
Transfer:
Processing within the EEA
Data:
email address, name, IP address

Meta (Facebook, Instagram)

Only if the organisation enables this integration

Publishes an announcement or event to the organisation’s own page, and fetches those posts back for the information screen.

Role:
Publishing to social media
GDPR role:
Independent controller — no data processing agreement, its own terms apply
Country:
US / IE
Transfer:
EU-US Data Privacy Framework
Data:
published post and image content

Google reCAPTCHA

Blocks automated sign-ups and spam on the public forms.

Role:
Protection against abuse
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
US
Transfer:
EU-US Data Privacy Framework
Data:
IP address

Google Analytics

Only if the organisation enables this integration

Visitor statistics for the Aqlemy website. Loads only after consent via the cookie banner.

Role:
Website analytics
GDPR role:
Processor — data processing agreement (GDPR art. 28)
Country:
US
Transfer:
EU-US Data Privacy Framework
Data:
website usage statistics, IP address

PDOK (Kadaster)

Completes the address during registration, based on postcode and house number. The lookup is made straight from the browser of the person filling in the form, so the Kadaster also sees their IP address. The Kadaster is itself the controller for that lookup; there is no processing agreement for an open, freely accessible government service.

Role:
Lookup service
GDPR role:
Independent controller — no data processing agreement, its own terms apply
Country:
NL
Transfer:
Processing within the EEA
Data:
postcode and house number, IP address

OpenStreetMap Foundation

Only if the organisation enables this integration

Shows the map on the organisation’s public page, and turns its place name into coordinates for the weather on the information screen. The map is fetched by the visitor’s browser, so the OpenStreetMap Foundation receives their IP address. It is itself the controller for that; there is no contract, and there cannot be one for a freely accessible map service. The weather lookup does happen on our server: only the organisation’s location is sent there.

Role:
Lookup service
GDPR role:
Independent controller — no data processing agreement, its own terms apply
Country:
UK
Transfer:
European Commission adequacy decision
Data:
IP address, location of the organisation (not personal data)

Google Maps

Shows the map with the address, on our own “About us” page and — if the organisation has configured a Google Maps key — on its public page. The map is loaded by the visitor’s browser, so Google receives their IP address and sets cookies.

Role:
Lookup service
GDPR role:
Independent controller — no data processing agreement, its own terms apply
Country:
US
Transfer:
EU-US Data Privacy Framework
Data:
IP address

Open-Meteo (OpenMeteo GmbH)

Only if the organisation enables this integration

Supplies the weather for the information screen. The request is made by our server, not by the screen, and contains only the organisation’s coordinates.

Role:
Lookup service
GDPR role:
No processor relationship — no personal data is sent
Country:
CH
Transfer:
European Commission adequacy decision
Data:
location of the organisation (not personal data)

What we deliberately do NOT outsource

These often sit with a third party. We do them ourselves.

  • Location on sign-inThe city and country on a sign-in are derived from a database file on our own server. No IP address goes to an external service.
  • The databaseThe database runs on the same server as the platform, not on a third party’s cloud service.
  • The typefaceThe typefaces sit on our own server and ship with the site when it is built. Nothing is fetched from Google when a page, the portal or an information screen is viewed, so Google never sees a visitor’s IP address.
  • The AI assistant and automatic translationThe language model runs on our own hardware. No student, member or financial data goes to OpenAI, Google or any other provider. Automatic translation of announcements, events, holidays and newsletters runs through it too: that text never leaves our server.